arrow
Return

Revisiting Higher-Order Masked Comparison for Lattice-Based Cryptography: Algorithms and Bit-Sliced Implementations

delete2023-02-01
delete6
delete
OA
AI
J
Jan-Pieter D’Anvers *
M
Michiel Van Beirendonck
I
Ingrid Verbauwhede
DOI:10.1109/TC.2022.3197074delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Marked comparison is one of the most expensive operations in side-channel secure implementations of lattice-based post-quantum cryptography, especially for higher masking orders. First, we introduce two new masked comparison algorithms, which improve the arithmetic comparison of D'Anvers et al. (2021) and the hybrid comparison method of Coron et al. (2021) respectively. We then look into implementation-specific optimizations, and show that small specific adaptations can have a significant impact on the overall performance. Finally, we implement various state-of-the-art comparison algorithms and benchmark them on the same platform (ARM-Cortex M4) to allow a fair comparison between them. We improve on the arithmetic comparison of D'Anvers et al. with a factor asymptotic to 20% by using Galois Field multiplications and the hybrid comparison of Coron et al. with a factor asymptotic to 25% by streamlining the design. Our implementation-specific improvements allow a speedup of a straightforward comparison implementation of asymptotic to 33%. We discuss the differences between the various algorithms and provide the implementations and a testing framework to ease future research.
Keywords:
Encryption
Arithmetic
Security
Side-channel attacks
Costs
Standards
NIST
Post-quantum cryptography
lattice-based cryptography
side-channel protection
masking

Journal

IEEE Transactions on Computers cover
IEEE Transactions on Computers
IF:
3.8
Papers:
5.3K
Citations:
9.8K

Organization

K
KU Leuven
Scholars:
5.7W
Papers: 5.2W
Citations: 8.1W